Clickfix on macOS: AppleScript Stealer, Terminal Phishing, and C2 Infrastructure
Summary
A macOS ClickFix campaign uses fake security prompts to push victims into running AppleScript via Terminal, stealing browser data, crypto wallets, and documents without any download.
- Published
- Collected
Skip to content